EMmind MTL system architecture
This page maps the MTL edition. Public EMmind inherited the same three-application shape at the 2026-02-25 import boundary but runs on separate AWS infrastructure. The imported public snapshot did not contain the MTL Google verification modules shown below.
System context
cbt-core applies the global /api prefix. The frontend clients use paths such as /line/users and /admin/users, which means each deployed APP_API_BASE_URL must already include /api or otherwise route those calls to the prefixed API.
In AWS, these logical services run as EC2-hosted container targets behind Application Load Balancers, not as ECS services. See infrastructure and deployment for the environment-specific routing and resource map.
Employee entry and identity flow
The default Google verification lifetime is 86,400 seconds. Protected employee APIs use AuthJwtGuard, LineAuthGuard, and GoogleAuthGuard. Account/profile and consent endpoints use LINE authentication without the Google guard so the gate can be completed.
Main employee data flow
CMS path
The current CMS server modules call read endpoints only. The core API exposes additional create, update, delete, notification, and reset operations that are not wired into the checked-out CMS integration modules.